Our takeRevolut confirms an unauthorized party used a legitimate government email domain to fraudulently request and obtain customer data. They have notified affected customers and regulators; treat any unexpected government-style contact as suspicious and verify independently.Cyber Resilience desk
Sources (2)
- techcrunch_sec · techcrunch_sec
- infosec_mag · infosec_mag
What this means for you — Security leader:Verify all incoming government or law-enforcement data requests through a documented out-of-band process before disclosure. Update your incident response plan to treat impersonated official domains as a high-priority social engineering vector.
What this means for you — Lean IT orgs:If a government agency or police force emails you asking for customer or staff data, call them on a known official number to confirm before sending anything. Treat any urgent-looking request as suspicious until verified.
What this means for you — MSP:Review client processes for handling official data requests; ensure verification always happens via a second channel. Add impersonated-authority scenarios to tabletop exercises and vendor security questionnaires.
What this means for you — Researcher:Track how threat actors are leveraging spoofed government domains to bypass KYC/AML controls at fintechs. This incident highlights gaps in request-validation procedures that rely primarily on email domain trust.